English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22147
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Apache À¥¼­¹ö´Â WebDAV¸¦ ÅëÇÑ µð·ºÅ丮 ¸®½ºÆÃ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
WebDAV (Web Distributed Authoring and Versioning)´Â »ç¿ëÀÚµéÀÌ HTTP ÇÁ·ÎÅäÄÝÀ» ÀÌ¿ëÇÏ¿© ¹®¼­µéÀ» »ý¼º, ÆíÁý, °øÀ¯ÇÒ ¼ö ÀÖ°Ô ÇØ ÁÖ´Â HTTPÀÇ ºÎ°¡±â´É(extension) ÀÌ´Ù. Ưº°ÇÑ REQUEST METHODÀÎ PROPFIND´Â »ç¿ëÀÚµéÀÌ µð½ºÇ÷¹ÀÌ ¸í, ¸¶Áö¸· ¼öÁ¤µÈ ³¯Â¥ µî°ú °°Àº ÀÚ¿ø¿¡ °üÇÑ Á¤º¸¸¦ °Ë»öÇØ º¼ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. SuSE 6.4¿¡ µðÆúÆ®·Î ¼³Ä¡µÈ Apache À¥¼­¹ö´Â ¼­¹öÀÇ Àüü ÆÄÀÏ ±¸Á¶¸¦ ´ë»óÀ¸·Î ÇÏ´Â WebDAV¸¦ °¡Áö°í ÀÖ´Ù. Apache À¥¼­¹ö·Î Ưº°ÇÏ°Ô ¸¸µé¾îÁø ¿äûÀ» º¸³¿À¸·Î½á µð·ºÅ丮 ¸®½ºÆÃ Á¤º¸¸¦ ¾ò¾î³¾ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://online.securityfocus.com/bid/1656
http://www.iss.net/security_center/static/5204.php

* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû:
Apache HTTP ¼­¹ö ¸ðµç ¹öÀü
SuSE Linux ¸ðµç ¹öÀü
ÇØ°áÃ¥ WebDAV ¸ðµâÀ» ÀÛµ¿ÁßÁö ½ÃÄÑ¾ß ÇÑ´Ù. ÀÛµ¿ÁßÁö ½Ã۱â À§Çؼ­´Â:

1. WebDAV·Î ¿ÀÇÂÇØ ³õ°íÀÚ ÇÏ´Â °¢°¢ÀÇ µð·ºÅ丮¿¡ ´ëÇØ httpd.conf¿¡ ÀÖ´Â ´ÙÀ½ ¿£Æ®¸®µéÀ» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù:

<Directory /webdav/directory/goes/here>
#add other directives as needed such as Order allow,deny
<IfDefine DAV>
DAV On
</IfDefine>
</Directory>

Apache¸¦ ÁßÁöÇϰí Àç½ÃÀÛÇÑ´Ù.

2. WebDAV¸¦ ¿ÏÀüÈ÷ ÀÛµ¿ÁßÁö ½Ã۱â À§Çؼ­´Â httpd.conf¿¡¼­ ´ÙÀ½ ¿£Æ®¸®µéÀ» ¿ì¼± ã´Â´Ù:

<IfDefine DAV>
DAV On
</IfDefine>

±×¸®°í "On"À» "Off"·Î ¹Ù²Û´Ù.
µðÆúÆ®·Î´Â "/usr/local/httpd/htdocs" ¸¸ÀÌ IfDefine DAV Áö½ÃÀÚ¸¦ °¡Áø À¯ÀÏÇÑ µð·ºÅ丮ÀÌ´Ù. ¶ÇÇÑ ÀÌ Áö½ÃÀÚ¸¦ °¡Áø ´Ù¸¥ µð·ºÅ丮µéÀÌ ÀÖ´Ù¸é ¸¶Âù°¡Áö·Î ¹Ù²Ù¾î¾ß ÇÑ´Ù.

Apache¸¦ ÁßÁöÇϰí Àç½ÃÀÛÇÑ´Ù.

3. WebDAV ¸ðµâ¾øÀÌ Apache¸¦ Àç½ÃÀÛ½Ã۱â À§Çؼ­´Â /etc/rc.d/rc3.d/S20apache ÆÄÀÏÀ» ÆíÁýÇÏ¿© ´ÙÀ½ ¶óÀÎÀ» ÁÖ¼®Ã³¸®("#") ÇØ¾ß ÇÑ´Ù:

test -e /usr/lib/apache/libdav.so && MODULES="-D DAV $MODULES"

´ÙÀ½¹ø Apache ½ÃÀÛ ½Ã¿¡ ÀÌ ¸ðµâÀº Æ÷ÇÔµÇÁö ¾ÊÀ» °ÍÀÌ´Ù.

-- ¶Ç´Â --

SuSE LinuxÀÇ °æ¿ì:
´ÙÀ½ SuSE º¸¾È°ü·Ã °øÁö¸¦ ÂüÁ¶ÇÏ¿© ApacheÀÇ ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://online.securityfocus.com/advisories/2609
°ü·Ã URL CVE-2000-0869 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)